Description
Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery.

This issue affects Hide My WP Ghost: from n/a through 7.0.09.
Published: 2026-09-08
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Server Side Request Forgery enabling arbitrary HTTP requests and potential internal network exposure
Action: Immediate Patch
AI Analysis

Impact

The Hide My WP Ghost plugin contains an SSRF flaw that allows an attacker to coerce the plugin into sending HTTP requests to arbitrary destinations. This can lead to exposure of sensitive internal resources, retrieval of restricted data, or commutation of further attacks against the host system. The weakness is characterized by CWE‑918 and is considered a medium‑high risk vulnerability.

Affected Systems

WordPress sites utilizing the Hide My WP Ghost plugin from any pre‑7.0.10 release. The flaw exists in all versions up to and including 7.0.09. Site administrators should verify the installed plugin version and determine if it falls within the affected range.

Risk and Exploitability

The CVSS score of 7.2 indicates a Moderate to High severity. The EPSS score is not available, so the current exploitation probability cannot be quantified, but the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via HTTP requests that the plugin accepts. If exploited, an attacker could use the SSRF to enumerate internal services or exfiltrate data, potentially creating a foothold for additional compromises.

Generated by OpenCVE AI on September 8, 2026 at 08:20 UTC.

Remediation

Vendor Solution

Update the WordPress Hide My WP Ghost Plugin to the latest available version (at least 7.0.10).


OpenCVE Recommended Actions

  • Update Hide My WP Ghost to version 7.0.10 or later as released by John Darrel
  • If an immediate update is not possible, disable the plugin or remove it from the WordPress installation to prevent exploitation
  • Implement network filtering or a WAF rule to block or restrict outbound HTTP requests initiated by WordPress plugins to mitigate SSRF exposure

Generated by OpenCVE AI on September 8, 2026 at 08:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared John Darrel
John Darrel hide My Wp Ghost
Wordpress
Wordpress wordpress
Vendors & Products John Darrel
John Darrel hide My Wp Ghost
Wordpress
Wordpress wordpress

Tue, 08 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery. This issue affects Hide My WP Ghost: from n/a through 7.0.09.
Title WordPress Hide My WP Ghost plugin <= 7.0.09 - Server Side Request Forgery (SSRF) vulnerability
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

John Darrel Hide My Wp Ghost
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-08T10:34:56.294Z

Reserved: 2026-08-27T12:24:38.076Z

Link: CVE-2026-81806

cve-icon Vulnrichment

Updated: 2026-09-08T10:31:44.738Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T08:17:13.267

Modified: 2026-09-08T13:12:58.310

Link: CVE-2026-81806

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T08:30:17Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)